NULL Pointer Dereference in MIT Kerberos 5 Levels Affected Products
CVE-2026-107778

7.1HIGH

Key Information:

Vendor

Mit

Status
Vendor
CVE Published:
8 October 2026

What is CVE-2026-107778?

The vulnerability in MIT Kerberos 5 (krb5) version 1.22.2 stems from a NULL pointer dereference found in the make_cred_list() function within rd_cred.c. This flaw enables authenticated Kerberos clients to inadvertently crash services by transmitting mismatched KRB-CRED arrays. Attackers can exploit this by sending forwarded credentials containing a greater number of tickets than the accompanying ticket_info entries through the gss_accept_sec_context() function, leading to a denial of service for GSS-API acceptor services.

Affected Version(s)

krb5 0 <= 1.22.2

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Tristan Madani
.